![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: qvo6 habe ich mir leider eingefangen wie werde ich das wieder los ich hab keine ahnungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #1 |
![]() | qvo6 habe ich mir leider eingefangen wie werde ich das wieder los ich hab keine ahnung qvo6 dieses Ding habe ich mir eingefangen bekomme es nicht mehr runter vom Lepptop ich suche schon die ganze zeit im Internet. Habe auch kaum Ahnung vom Leppi ich weis das da win 8 drauf ist bitte helft mir. Habe schon einiges versucht. Habe grade das FRST-Bit runter geladen und durchlaufen lassen (das habe ich hier in Forum gefunden) folgende kam raus e: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Program Files (x86)\PHotkey\PHotkey.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe () C:\Program Files (x86)\PHotkey\ATouch64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe () C:\Program Files (x86)\PHotkey\POSD.exe () C:\Program Files (x86)\PHotkey\GPMTray.exe (TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\ArcSoft TV 5.0\TMTV5Monitor.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-17] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917176 2012-09-05] (Synaptics Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1 HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [45056 2012-07-26] (Microsoft Corporation) HKCU\...\Run: [VeohPlugin] - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [4686848 2013-08-04] (Veoh Networks) MountPoints2: {08e89473-2538-11e3-bebb-7054d2864a6b} - "G:\LaunchU3.exe" -a HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-20] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [258576 2012-07-30] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [247144 2012-10-11] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [203112 2012-10-11] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://about:Tabs/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = QVO6 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = QVO6 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe QVO6 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {43477775-D207-470D-9D20-2EE40EBBDCBE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKCU - {43477775-D207-470D-9D20-2EE40EBBDCBE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = Tcpip\Parameters: [DhcpNameServer] 62.109.121.2 62.109.121.1 FireFox: ======== FF ProfilePath: C:\Users\Tanja\AppData\Roaming\Mozilla\Firefox\Profiles\id0j00ql.default-1381350657015 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-13] (CyberLink) R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-13] (CyberLink) R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [805888 2012-11-29] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] () R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [559168 2013-03-12] (RealNetworks, Inc.) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2012-10-19] () R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132480 2012-10-01] (Motorola Solutions, Inc.) S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1337216 2012-10-01] (Motorola Solutions, Inc.) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2012-11-14] (ITE ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4309032 2012-10-10] (Intel Corporation) R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON) R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider) R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-10 00:29 - 2013-10-10 00:30 - 00020166 _____ C:\Users\Tanja\Downloads\Addition.txt 2013-10-10 00:28 - 2013-10-10 00:28 - 00000000 ____D C:\FRST 2013-10-10 00:27 - 2013-10-10 00:27 - 01954124 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-10 00:27 - 2013-10-10 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-10 00:25 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-10 00:24 - 2013-10-10 00:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tanja\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-10 00:22 - 2013-10-10 00:22 - 00891167 _____ C:\Users\Tanja\Downloads\SecurityCheck.exe 2013-10-10 00:13 - 2013-10-10 00:13 - 00303464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-09 23:55 - 2013-10-09 23:55 - 00000000 ____D C:\Program Files (x86)\ESET 2013-10-09 23:44 - 2013-10-09 23:44 - 02347384 _____ (ESET) C:\Users\Tanja\Desktop\esetsmartinstaller_enu.exe 2013-10-09 23:24 - 2013-10-09 23:24 - 00000093 _____ C:\Users\Tanja\AppData\Roaming\WB.CFG 2013-10-09 23:24 - 2013-10-09 23:24 - 00000006 _____ C:\Users\Tanja\AppData\Roaming\WBPU-TTL.DAT 2013-10-09 23:13 - 2013-10-09 23:13 - 00000000 _____ C:\autoexec.bat 2013-10-09 23:12 - 2013-10-10 00:20 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-09 23:12 - 2013-10-09 23:12 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-09 22:40 - 2013-10-09 22:41 - 22537616 _____ (Mozilla) C:\Users\Tanja\Downloads\Firefox_Setup_de24.0.exe 2013-10-09 22:30 - 2013-10-09 22:30 - 00000000 ____D C:\Users\Tanja\Desktop\Alte Firefox-Daten 2013-10-09 22:24 - 2013-10-10 00:24 - 00000306 _____ C:\Windows\Tasks\DigitalSite.job 2013-10-09 22:24 - 2013-10-09 23:46 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\DigitalSite 2013-10-09 22:24 - 2013-10-09 22:27 - 00000000 ____D C:\ProgramData\eSafe 2013-10-09 22:24 - 2013-10-09 22:24 - 00002644 _____ C:\Windows\System32\Tasks\DigitalSite 2013-10-09 22:24 - 2013-10-09 22:24 - 00000000 ____D C:\ProgramData\Babylon 2013-10-09 18:20 - 2013-10-09 18:54 - 00000000 ____D C:\Users\Tanja\Desktop\MUSIK NEU 2013-10-09 08:24 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-09 08:24 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-09 08:24 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-09 08:24 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-09 08:24 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-09 08:24 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-09 08:24 - 2013-07-06 02:15 - 00652288 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 08:24 - 2013-07-04 04:13 - 00541696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 08:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-10-09 08:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-10-09 08:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-09 08:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-09 08:24 - 2013-04-29 00:28 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-09 08:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-09 08:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-09 08:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-10-09 08:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-09 08:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-09 08:23 - 2013-08-23 07:11 - 04040192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 08:23 - 2013-07-20 00:13 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 08:23 - 2013-07-20 00:13 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 08:23 - 2013-07-06 00:02 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 08:23 - 2013-07-06 00:01 - 00210560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-09 08:23 - 2013-07-02 03:41 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2013-10-09 08:23 - 2013-07-02 03:41 - 00337752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-10-09 08:23 - 2013-07-02 03:41 - 00213336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-10-09 08:23 - 2013-07-02 00:14 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbprint.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00623448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00498008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00079192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00021848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-09 08:23 - 2013-06-29 05:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 08:23 - 2013-06-29 05:07 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 08:23 - 2013-06-29 05:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-09 08:23 - 2013-06-29 05:06 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-09 08:23 - 2013-06-22 07:45 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 08:23 - 2013-06-22 07:45 - 00054488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-10-09 08:23 - 2013-05-27 01:17 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-09 08:23 - 2013-05-27 00:59 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 08:23 - 2013-05-25 05:15 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 08:23 - 2013-05-25 04:32 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-09-25 00:30 - 2013-09-25 00:31 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install 2013-09-25 00:28 - 2013-09-25 00:28 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Sony 2013-09-25 00:27 - 2013-09-25 00:27 - 00000562 _____ C:\Windows\wmsetup.log 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Local\Downloaded Installations 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Program Files (x86)\Sony 2013-09-25 00:18 - 2013-09-25 00:18 - 00000649 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WALKMAN.lnk 2013-09-25 00:13 - 2013-09-25 00:15 - 00000000 ____D C:\Users\Tanja\Desktop\Gesundheit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Top 12.11 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Stressbewältigung durch die Praxis der Achtsamkeit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Die heilendekraft der Achtsamkeit 2013-09-25 00:04 - 2013-09-25 00:04 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2013-09-24 23:42 - 2013-09-24 23:42 - 00000000 ____D C:\Users\Tanja\Desktop\etwas neuer 2013-09-24 23:41 - 2013-09-24 23:42 - 00000000 ____D C:\Users\Tanja\Desktop\Musik 2013-09-17 12:41 - 2013-09-17 12:42 - 00000000 ____D C:\Users\Tanja\Desktop\Magistrat 2013-09-12 18:40 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-09-12 16:28 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-09-12 16:28 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2013-09-12 16:28 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-12 16:28 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2013-09-12 16:28 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2013-09-12 16:28 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 16:28 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-12 16:28 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-09-12 16:28 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-09-12 16:28 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2013-09-12 16:28 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll 2013-09-12 16:26 - 2013-09-12 16:31 - 00000323 _____ C:\Users\Tanja\Desktop\Neues Textdokument.txt ==================== One Month Modified Files and Folders ======= 2013-10-10 00:30 - 2013-10-10 00:29 - 00020166 _____ C:\Users\Tanja\Downloads\Addition.txt 2013-10-10 00:28 - 2013-10-10 00:28 - 00000000 ____D C:\FRST 2013-10-10 00:27 - 2013-10-10 00:27 - 01954124 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-10 00:27 - 2013-10-10 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-10 00:24 - 2013-10-10 00:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tanja\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-10 00:24 - 2013-10-09 22:24 - 00000306 _____ C:\Windows\Tasks\DigitalSite.job 2013-10-10 00:24 - 2013-04-15 21:46 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-10 00:24 - 2013-04-15 21:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-10 00:24 - 2013-04-08 20:44 - 01277368 _____ C:\Windows\WindowsUpdate.log 2013-10-10 00:22 - 2013-10-10 00:22 - 00891167 _____ C:\Users\Tanja\Downloads\SecurityCheck.exe 2013-10-10 00:20 - 2013-10-09 23:12 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-10 00:19 - 2013-04-08 20:52 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1257113705-4000422617-458715297-1002 2013-10-10 00:15 - 2013-07-03 19:58 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-10 00:15 - 2013-04-08 20:48 - 00000000 ____D C:\Users\Tanja\Documents\Youcam 2013-10-10 00:13 - 2013-10-10 00:13 - 00303464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-10 00:13 - 2013-08-16 23:59 - 00071346 _____ C:\Windows\PFRO.log 2013-10-10 00:13 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 00:13 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2013-10-10 00:08 - 2013-07-03 19:58 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-10 00:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-10-09 23:55 - 2013-10-09 23:55 - 00000000 ____D C:\Program Files (x86)\ESET 2013-10-09 23:50 - 2013-04-19 08:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-09 23:50 - 2013-04-19 08:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-09 23:46 - 2013-10-09 22:24 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\DigitalSite 2013-10-09 23:44 - 2013-10-09 23:44 - 02347384 _____ (ESET) C:\Users\Tanja\Desktop\esetsmartinstaller_enu.exe 2013-10-09 23:24 - 2013-10-09 23:24 - 00000093 _____ C:\Users\Tanja\AppData\Roaming\WB.CFG 2013-10-09 23:24 - 2013-10-09 23:24 - 00000006 _____ C:\Users\Tanja\AppData\Roaming\WBPU-TTL.DAT 2013-10-09 23:21 - 2013-06-26 22:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-09 23:13 - 2013-10-09 23:13 - 00000000 _____ C:\autoexec.bat 2013-10-09 23:12 - 2013-10-09 23:12 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-09 22:41 - 2013-10-09 22:40 - 22537616 _____ (Mozilla) C:\Users\Tanja\Downloads\Firefox_Setup_de24.0.exe 2013-10-09 22:30 - 2013-10-09 22:30 - 00000000 ____D C:\Users\Tanja\Desktop\Alte Firefox-Daten 2013-10-09 22:27 - 2013-10-09 22:24 - 00000000 ____D C:\ProgramData\eSafe 2013-10-09 22:25 - 2013-04-13 17:36 - 00000000 ____D C:\Users\Tanja\AppData\Local\Mozilla 2013-10-09 22:24 - 2013-10-09 22:24 - 00002644 _____ C:\Windows\System32\Tasks\DigitalSite 2013-10-09 22:24 - 2013-10-09 22:24 - 00000000 ____D C:\ProgramData\Babylon 2013-10-09 22:24 - 2013-04-08 20:46 - 00002159 _____ C:\Users\Public\Desktop\eBay.lnk 2013-10-09 22:24 - 2013-04-08 20:46 - 00001746 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-09 19:45 - 2013-07-28 09:27 - 00000000 ____D C:\Windows\system32\MRT 2013-10-09 19:43 - 2012-11-14 08:51 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 18:54 - 2013-10-09 18:20 - 00000000 ____D C:\Users\Tanja\Desktop\MUSIK NEU 2013-10-09 12:59 - 2012-11-14 07:45 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-10-09 12:59 - 2012-11-14 07:45 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-10-09 12:59 - 2012-07-26 09:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-04 23:45 - 2013-04-08 20:45 - 00000000 ____D C:\Users\Tanja\AppData\Local\Packages 2013-10-04 23:45 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-10-02 03:38 - 2013-05-17 00:39 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-02 03:38 - 2013-05-17 00:39 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-25 00:31 - 2013-09-25 00:30 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install 2013-09-25 00:28 - 2013-09-25 00:28 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Sony 2013-09-25 00:27 - 2013-09-25 00:27 - 00000562 _____ C:\Windows\wmsetup.log 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Local\Downloaded Installations 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Program Files (x86)\Sony 2013-09-25 00:18 - 2013-09-25 00:18 - 00000649 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WALKMAN.lnk 2013-09-25 00:15 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Gesundheit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Top 12.11 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Stressbewältigung durch die Praxis der Achtsamkeit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Die heilendekraft der Achtsamkeit 2013-09-25 00:04 - 2013-09-25 00:04 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2013-09-25 00:04 - 2013-08-22 07:55 - 00002316 _____ C:\Windows\setupact.log 2013-09-24 23:42 - 2013-09-24 23:42 - 00000000 ____D C:\Users\Tanja\Desktop\etwas neuer 2013-09-24 23:42 - 2013-09-24 23:41 - 00000000 ____D C:\Users\Tanja\Desktop\Musik 2013-09-24 22:41 - 2013-08-30 00:22 - 00000000 ____D C:\Users\Tanja\Desktop\muki 2013-09-23 01:28 - 2013-10-09 08:24 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-09 08:24 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 00:55 - 2013-10-09 08:24 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-09 08:24 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-09 08:24 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-09 08:24 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-17 12:42 - 2013-09-17 12:41 - 00000000 ____D C:\Users\Tanja\Desktop\Magistrat 2013-09-15 16:01 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-09-12 20:18 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-09-12 20:18 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-12 16:31 - 2013-09-12 16:26 - 00000323 _____ C:\Users\Tanja\Desktop\Neues Textdokument.txt Some content of TEMP: ==================== C:\Users\Tanja\AppData\Local\Temp\AppLauncher.exe C:\Users\Tanja\AppData\Local\Temp\htmlayout.dll C:\Users\Tanja\AppData\Local\Temp\ICReinstall_CodecPackage.exe C:\Users\Tanja\AppData\Local\Temp\Quarantine.exe C:\Users\Tanja\AppData\Local\Temp\SHSetup.exe C:\Users\Tanja\AppData\Local\Temp\uninst1.exe C:\Users\Tanja\AppData\Local\Temp\uninstall1247791765.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-29 15:06 ==================== End Of Log ============================ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Tanja (administrator) on BONSAI on 10-10-2013 00:39:56 Running from C:\Users\Tanja\Downloads Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Program Files (x86)\PHotkey\PHotkey.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe () C:\Program Files (x86)\PHotkey\ATouch64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe () C:\Program Files (x86)\PHotkey\POSD.exe () C:\Program Files (x86)\PHotkey\GPMTray.exe (TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\ArcSoft TV 5.0\TMTV5Monitor.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-17] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917176 2012-09-05] (Synaptics Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1 HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [45056 2012-07-26] (Microsoft Corporation) HKCU\...\Run: [VeohPlugin] - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [4686848 2013-08-04] (Veoh Networks) MountPoints2: {08e89473-2538-11e3-bebb-7054d2864a6b} - "G:\LaunchU3.exe" -a HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-20] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [258576 2012-07-30] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [247144 2012-10-11] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [203112 2012-10-11] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://about:Tabs/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = QVO6 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = QVO6 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe QVO6 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {43477775-D207-470D-9D20-2EE40EBBDCBE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CCB06173&ts=1381350264&type=default&q={searchTerms} SearchScopes: HKCU - {43477775-D207-470D-9D20-2EE40EBBDCBE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = Tcpip\Parameters: [DhcpNameServer] 62.109.121.2 62.109.121.1 FireFox: ======== FF ProfilePath: C:\Users\Tanja\AppData\Roaming\Mozilla\Firefox\Profiles\id0j00ql.default-1381350657015 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-13] (CyberLink) R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-13] (CyberLink) R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [805888 2012-11-29] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] () R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [559168 2013-03-12] (RealNetworks, Inc.) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2012-10-19] () R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132480 2012-10-01] (Motorola Solutions, Inc.) S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1337216 2012-10-01] (Motorola Solutions, Inc.) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2012-11-14] (ITE ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4309032 2012-10-10] (Intel Corporation) R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON) R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider) R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-10 00:35 - 2013-10-10 00:35 - 00037383 _____ C:\Users\Tanja\Desktop\Neues Textdokument (2).txt 2013-10-10 00:29 - 2013-10-10 00:30 - 00020166 _____ C:\Users\Tanja\Downloads\Addition.txt 2013-10-10 00:28 - 2013-10-10 00:28 - 00000000 ____D C:\FRST 2013-10-10 00:27 - 2013-10-10 00:27 - 01954124 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-10 00:27 - 2013-10-10 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-10 00:25 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-10 00:24 - 2013-10-10 00:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tanja\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-10 00:22 - 2013-10-10 00:22 - 00891167 _____ C:\Users\Tanja\Downloads\SecurityCheck.exe 2013-10-10 00:13 - 2013-10-10 00:13 - 00303464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-09 23:55 - 2013-10-09 23:55 - 00000000 ____D C:\Program Files (x86)\ESET 2013-10-09 23:44 - 2013-10-09 23:44 - 02347384 _____ (ESET) C:\Users\Tanja\Desktop\esetsmartinstaller_enu.exe 2013-10-09 23:24 - 2013-10-09 23:24 - 00000093 _____ C:\Users\Tanja\AppData\Roaming\WB.CFG 2013-10-09 23:24 - 2013-10-09 23:24 - 00000006 _____ C:\Users\Tanja\AppData\Roaming\WBPU-TTL.DAT 2013-10-09 23:13 - 2013-10-09 23:13 - 00000000 _____ C:\autoexec.bat 2013-10-09 23:12 - 2013-10-10 00:20 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-09 23:12 - 2013-10-09 23:12 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-09 22:40 - 2013-10-09 22:41 - 22537616 _____ (Mozilla) C:\Users\Tanja\Downloads\Firefox_Setup_de24.0.exe 2013-10-09 22:30 - 2013-10-09 22:30 - 00000000 ____D C:\Users\Tanja\Desktop\Alte Firefox-Daten 2013-10-09 22:24 - 2013-10-10 00:24 - 00000306 _____ C:\Windows\Tasks\DigitalSite.job 2013-10-09 22:24 - 2013-10-09 23:46 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\DigitalSite 2013-10-09 22:24 - 2013-10-09 22:27 - 00000000 ____D C:\ProgramData\eSafe 2013-10-09 22:24 - 2013-10-09 22:24 - 00002644 _____ C:\Windows\System32\Tasks\DigitalSite 2013-10-09 22:24 - 2013-10-09 22:24 - 00000000 ____D C:\ProgramData\Babylon 2013-10-09 18:20 - 2013-10-09 18:54 - 00000000 ____D C:\Users\Tanja\Desktop\MUSIK NEU 2013-10-09 08:24 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-09 08:24 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-09 08:24 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-09 08:24 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-09 08:24 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-09 08:24 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-09 08:24 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-09 08:24 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-09 08:24 - 2013-07-06 02:15 - 00652288 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 08:24 - 2013-07-04 04:13 - 00541696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 08:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-10-09 08:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-10-09 08:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-09 08:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-09 08:24 - 2013-04-29 00:28 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-09 08:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-09 08:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-09 08:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-09 08:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-10-09 08:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-09 08:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-09 08:23 - 2013-08-23 07:11 - 04040192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 08:23 - 2013-07-20 00:13 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 08:23 - 2013-07-20 00:13 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 08:23 - 2013-07-06 00:02 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 08:23 - 2013-07-06 00:01 - 00210560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-09 08:23 - 2013-07-02 03:41 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2013-10-09 08:23 - 2013-07-02 03:41 - 00337752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-10-09 08:23 - 2013-07-02 03:41 - 00213336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-10-09 08:23 - 2013-07-02 00:14 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbprint.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00623448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00498008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00079192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-09 08:23 - 2013-07-01 03:42 - 00021848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-09 08:23 - 2013-06-29 05:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 08:23 - 2013-06-29 05:07 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 08:23 - 2013-06-29 05:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-09 08:23 - 2013-06-29 05:06 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-09 08:23 - 2013-06-22 07:45 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 08:23 - 2013-06-22 07:45 - 00054488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-10-09 08:23 - 2013-05-27 01:17 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-09 08:23 - 2013-05-27 00:59 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 08:23 - 2013-05-25 05:15 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 08:23 - 2013-05-25 04:32 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-09-25 00:30 - 2013-09-25 00:31 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install 2013-09-25 00:28 - 2013-09-25 00:28 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Sony 2013-09-25 00:27 - 2013-09-25 00:27 - 00000562 _____ C:\Windows\wmsetup.log 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Local\Downloaded Installations 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Program Files (x86)\Sony 2013-09-25 00:18 - 2013-09-25 00:18 - 00000649 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WALKMAN.lnk 2013-09-25 00:13 - 2013-09-25 00:15 - 00000000 ____D C:\Users\Tanja\Desktop\Gesundheit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Top 12.11 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Stressbewältigung durch die Praxis der Achtsamkeit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Die heilendekraft der Achtsamkeit 2013-09-25 00:04 - 2013-09-25 00:04 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2013-09-24 23:42 - 2013-09-24 23:42 - 00000000 ____D C:\Users\Tanja\Desktop\etwas neuer 2013-09-24 23:41 - 2013-09-24 23:42 - 00000000 ____D C:\Users\Tanja\Desktop\Musik 2013-09-17 12:41 - 2013-09-17 12:42 - 00000000 ____D C:\Users\Tanja\Desktop\Magistrat 2013-09-12 18:40 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-09-12 16:28 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-09-12 16:28 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2013-09-12 16:28 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-12 16:28 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2013-09-12 16:28 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2013-09-12 16:28 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 16:28 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-12 16:28 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-12 16:28 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll 2013-09-12 16:28 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-09-12 16:28 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-09-12 16:28 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2013-09-12 16:28 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll 2013-09-12 16:26 - 2013-09-12 16:31 - 00000323 _____ C:\Users\Tanja\Desktop\Neues Textdokument.txt ==================== One Month Modified Files and Folders ======= 2013-10-10 00:35 - 2013-10-10 00:35 - 00037383 _____ C:\Users\Tanja\Desktop\Neues Textdokument (2).txt 2013-10-10 00:34 - 2013-04-08 20:44 - 01277576 _____ C:\Windows\WindowsUpdate.log 2013-10-10 00:30 - 2013-10-10 00:29 - 00020166 _____ C:\Users\Tanja\Downloads\Addition.txt 2013-10-10 00:28 - 2013-10-10 00:28 - 00000000 ____D C:\FRST 2013-10-10 00:27 - 2013-10-10 00:27 - 01954124 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-10 00:27 - 2013-10-10 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-10 00:25 - 2013-10-10 00:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-10 00:24 - 2013-10-10 00:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tanja\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-10 00:24 - 2013-10-09 22:24 - 00000306 _____ C:\Windows\Tasks\DigitalSite.job 2013-10-10 00:24 - 2013-04-15 21:46 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-10 00:24 - 2013-04-15 21:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-10 00:22 - 2013-10-10 00:22 - 00891167 _____ C:\Users\Tanja\Downloads\SecurityCheck.exe 2013-10-10 00:20 - 2013-10-09 23:12 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-10 00:19 - 2013-04-08 20:52 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1257113705-4000422617-458715297-1002 2013-10-10 00:15 - 2013-07-03 19:58 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-10 00:15 - 2013-04-08 20:48 - 00000000 ____D C:\Users\Tanja\Documents\Youcam 2013-10-10 00:13 - 2013-10-10 00:13 - 00303464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-10 00:13 - 2013-08-16 23:59 - 00071346 _____ C:\Windows\PFRO.log 2013-10-10 00:13 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 00:13 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2013-10-10 00:08 - 2013-07-03 19:58 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-10 00:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-10-09 23:55 - 2013-10-09 23:55 - 00000000 ____D C:\Program Files (x86)\ESET 2013-10-09 23:50 - 2013-04-19 08:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-09 23:50 - 2013-04-19 08:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-09 23:46 - 2013-10-09 22:24 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\DigitalSite 2013-10-09 23:44 - 2013-10-09 23:44 - 02347384 _____ (ESET) C:\Users\Tanja\Desktop\esetsmartinstaller_enu.exe 2013-10-09 23:24 - 2013-10-09 23:24 - 00000093 _____ C:\Users\Tanja\AppData\Roaming\WB.CFG 2013-10-09 23:24 - 2013-10-09 23:24 - 00000006 _____ C:\Users\Tanja\AppData\Roaming\WBPU-TTL.DAT 2013-10-09 23:21 - 2013-06-26 22:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-09 23:13 - 2013-10-09 23:13 - 00000000 _____ C:\autoexec.bat 2013-10-09 23:12 - 2013-10-09 23:12 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-09 22:41 - 2013-10-09 22:40 - 22537616 _____ (Mozilla) C:\Users\Tanja\Downloads\Firefox_Setup_de24.0.exe 2013-10-09 22:30 - 2013-10-09 22:30 - 00000000 ____D C:\Users\Tanja\Desktop\Alte Firefox-Daten 2013-10-09 22:27 - 2013-10-09 22:24 - 00000000 ____D C:\ProgramData\eSafe 2013-10-09 22:25 - 2013-04-13 17:36 - 00000000 ____D C:\Users\Tanja\AppData\Local\Mozilla 2013-10-09 22:24 - 2013-10-09 22:24 - 00002644 _____ C:\Windows\System32\Tasks\DigitalSite 2013-10-09 22:24 - 2013-10-09 22:24 - 00000000 ____D C:\ProgramData\Babylon 2013-10-09 22:24 - 2013-04-08 20:46 - 00002159 _____ C:\Users\Public\Desktop\eBay.lnk 2013-10-09 22:24 - 2013-04-08 20:46 - 00001746 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-09 19:45 - 2013-07-28 09:27 - 00000000 ____D C:\Windows\system32\MRT 2013-10-09 19:43 - 2012-11-14 08:51 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 18:54 - 2013-10-09 18:20 - 00000000 ____D C:\Users\Tanja\Desktop\MUSIK NEU 2013-10-09 12:59 - 2012-11-14 07:45 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-10-09 12:59 - 2012-11-14 07:45 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-10-09 12:59 - 2012-07-26 09:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-04 23:45 - 2013-04-08 20:45 - 00000000 ____D C:\Users\Tanja\AppData\Local\Packages 2013-10-04 23:45 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-10-02 03:38 - 2013-05-17 00:39 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-02 03:38 - 2013-05-17 00:39 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-25 00:31 - 2013-09-25 00:30 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install 2013-09-25 00:28 - 2013-09-25 00:28 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\Sony 2013-09-25 00:27 - 2013-09-25 00:27 - 00000562 _____ C:\Windows\wmsetup.log 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Users\Tanja\AppData\Local\Downloaded Installations 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-09-25 00:27 - 2013-09-25 00:27 - 00000000 ____D C:\Program Files (x86)\Sony 2013-09-25 00:18 - 2013-09-25 00:18 - 00000649 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WALKMAN.lnk 2013-09-25 00:15 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Gesundheit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Top 12.11 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Stressbewältigung durch die Praxis der Achtsamkeit 2013-09-25 00:13 - 2013-09-25 00:13 - 00000000 ____D C:\Users\Tanja\Desktop\Die heilendekraft der Achtsamkeit 2013-09-25 00:04 - 2013-09-25 00:04 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2013-09-25 00:04 - 2013-08-22 07:55 - 00002316 _____ C:\Windows\setupact.log 2013-09-24 23:42 - 2013-09-24 23:42 - 00000000 ____D C:\Users\Tanja\Desktop\etwas neuer 2013-09-24 23:42 - 2013-09-24 23:41 - 00000000 ____D C:\Users\Tanja\Desktop\Musik 2013-09-24 22:41 - 2013-08-30 00:22 - 00000000 ____D C:\Users\Tanja\Desktop\muki 2013-09-23 01:28 - 2013-10-09 08:24 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-09 08:24 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-09 08:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 00:55 - 2013-10-09 08:24 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-09 08:24 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-09 08:24 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-09 08:24 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-09 08:24 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-17 12:42 - 2013-09-17 12:41 - 00000000 ____D C:\Users\Tanja\Desktop\Magistrat 2013-09-15 16:01 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-09-12 20:18 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-09-12 20:18 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-12 16:31 - 2013-09-12 16:26 - 00000323 _____ C:\Users\Tanja\Desktop\Neues Textdokument.txt Some content of TEMP: ==================== C:\Users\Tanja\AppData\Local\Temp\AppLauncher.exe C:\Users\Tanja\AppData\Local\Temp\htmlayout.dll C:\Users\Tanja\AppData\Local\Temp\ICReinstall_CodecPackage.exe C:\Users\Tanja\AppData\Local\Temp\Quarantine.exe C:\Users\Tanja\AppData\Local\Temp\SHSetup.exe C:\Users\Tanja\AppData\Local\Temp\uninst1.exe C:\Users\Tanja\AppData\Local\Temp\uninstall1247791765.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-29 15:06 ==================== End Of Log ============================ --- --- --- |
| Themen zu qvo6 habe ich mir leider eingefangen wie werde ich das wieder los ich hab keine ahnung |
| ahnung, eingefangen, farbar, farbar recovery scan tool, gefangen, gen, helft, icreinstall, inter, interne, keine ahnung, nicht mehr, online games, runter, suche, win, win 8, windowsapps |